Back

CVE-2001-1202

Cross-site scripting vulnerability in DeleGate 7.7.0 and 7.7.1 does not quote scripting commands within a "403 Forbidden" error page, which allows remote attackers to execute arbitrary Javascript on other clients via a URL that generates an error.

Published: Dec 28, 2001 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (4)

Vendor Product Version
delegate delegate 7.7.0
delegate delegate 7.7.1
delegate delegate 7.8.0
delegate delegate 7.8.1

GitHub Security Advisory GHSA-7hgq-qg3c-85g8

Cross-site scripting vulnerability in DeleGate 7.7.0 and 7.7.1 does not quote scripting commands...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 6.67%

Top 7% most likely to be exploited

Threat Score 32 / 100

Data Sources

NVD EPSS GitHub